Database/Kernel, userspace & hypervisor
Linux kernel NVMe target core (nvmet_req_complete submission-queue dereference): Nvmet_req_complete() dereferenced req
Impact
Nvmet_req_complete() dereferenced req to reach the submission queue after calling __nvmet_req_complete(), which a transport's queue_response implementation is allowed to free. Every completed command on the target passes through this function, so the use-after-free is on the hottest path in the process serving the cluster's block storage - and command completion is driven by whatever the remote initiator submitted.
Who can reach it
Remote, unauthenticated. Any initiator that can submit commands to the target reaches the completion path.
What to do
Kernel update caching the sq pointer before completion. Contain by network segmentation of the storage fabric.
References
Related entries
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
- Linux kernel (net/tls): The async decrypt completion released pages that the decrypt path never took a reference on, soCVE-2024-26582 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completionCVE-2024-26583 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and theCVE-2024-26584 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async crypto callback signalled completion before scheduling the transmit work, so theCVE-2024-26585 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.